diff --git a/docs/permissions/getting-started.md b/docs/permissions/getting-started.md index 0d542a6502..01a268f7ef 100644 --- a/docs/permissions/getting-started.md +++ b/docs/permissions/getting-started.md @@ -36,7 +36,7 @@ Like many other parts of Backstage, the permissions framework relies on informat ## Optionally add cookie-based authentication -Frontend requests initiated by the browser will not include a token in the `Authorization` header. If these requests check authorization through the permission framework, as done in plugins like TechDocs, then you'll need to set up cookie-based authentication. Refer to the ["Authenticate API requests"](https://github.com/backstage/backstage/blob/master/contrib/docs/tutorials/authenticate-api-requests.md) tutorial for a demonstration on how to implement this behavior. +Asset requests initiated by the browser will not include a token in the `Authorization` header. If these requests check authorization through the permission framework, as done in plugins like TechDocs, then you'll need to set up cookie-based authentication. Refer to the ["Authenticate API requests"](https://github.com/backstage/backstage/blob/master/contrib/docs/tutorials/authenticate-api-requests.md) tutorial for a demonstration on how to implement this behavior. ## Integrating the permission framework with your Backstage instance